From d3d39735ce0092cff5e4842cbb1f3d005e0273ef Mon Sep 17 00:00:00 2001 From: Jeremy Felt Date: Mon, 6 Mar 2017 08:05:33 +0000 Subject: [PATCH] Validate video and audio metadata. Merge of [40148] to the 4.5 branch. Built from https://develop.svn.wordpress.org/branches/4.5@40151 git-svn-id: http://core.svn.wordpress.org/branches/4.5@40090 1a063a9b-81f0-0310-95a4-ce76da25c4cd --- wp-admin/includes/media.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/wp-admin/includes/media.php b/wp-admin/includes/media.php index f324ae8caa..c694c3c754 100644 --- a/wp-admin/includes/media.php +++ b/wp-admin/includes/media.php @@ -3041,6 +3041,8 @@ function wp_read_video_metadata( $file ) { wp_add_id3_tag_data( $metadata, $data ); + $metadata = wp_kses_post_deep( $metadata ); + return $metadata; } @@ -3086,6 +3088,8 @@ function wp_read_audio_metadata( $file ) { wp_add_id3_tag_data( $metadata, $data ); + $metadata = wp_kses_post_deep( $metadata ); + return $metadata; }